From Command Injection To Meterpreter Shell – Detailed Tutorial 2018

Other than XSS and SQL Injection, there are number of different attack techniques against a web application. In this tutorial,we’ll exploit the DVWA Web Application with Command Injection Attack.

There are so many vulnerable web applications where players must locate and exploit vulnerabilities to progress through the story which contains various vulnerabilities like XSS, CSRF, SQLi, ReDoS, DOR, command injection, and so on.

There are a plenty of sources dedicated to teaching how to use the Metasploit Framework. In the article, we will examine how Metasploit is used
for server-side exploitation for testing potential web applications.

What is Command Injection ?

Command injection is a type of attack in which arbitrary operating system commands are executed on the host via a vulnerable web application (DVWA in our case). Usually, this occurs when an application passes unsafe user input from a form to the server, but this can also happen with cookies, HTTP headers, and other sources of data.

The ultimate goal of command injection is to execute the arbitrary commands on the host OS via a vulnerable command. These type of attacks are so much possible largely due to insufficient input validation.

Exploitation Setup –

You need to use a virtual machine (With Kali Linux as an attacker machine and Metasploitable2 which is a vulnerable machine). The first thing we need to do is open DVWA and log in using the default credentials (admin:password).

Metasploitable machine IP – 192.168.73.130

Kali Linux IP – 192.168.73.128

Next, browse to the “DVWA Security” tab and set the security level to “low” to make sure our exploit is run without any hiccups when we’re ready.

Now we can navigate to the “Command Execution” page showing on left hand side. For this attack to work, we have to ensure that the target application can communicate with our local machine. We can take advantage of the default functionality of this page to ping our attacking machine. Just enter the IP address and hit “submit.”

In situations like this, the application, which executes unwanted system commands, is like a pseudo system shell, and the attacker may use it
as an authorized system user.

Note, the commands are executed with the same privileges as the application and/or web server.

As already said, “Command injection attacks are possible in most cases because of lack of correct input data validation, which can be manipulated by the attacker (forms, cookies, HTTP headers etc.).”

We can also implement multiple commands simultaneously just by using && sign. For example:

Command: <IP> && ls -l

We can see that the application responded with the contents of the current directory at the bottom, which means that a command injection vulnerability exists. We will take advantage of this to launch our web delivery script next.

The first step is to open up a console and type in msfconsole to launch Metasploit Framework. It is the most popular way to launch Metasploit. It provides a user interface to access the entire Metasploit framework. Basic commands such as helpand showwill allow you to navigate through Metasploit.

Note – In addition to Metasploit commands, msfconsole will allow you to invoke underlying OS commands such as ping or nmap. This is helpful because it allows an attacker to execute routine tasks without leaving the console.

Metasploit contains a useful module that hosts a payload on a server created on the attacking machine. The web delivery script is run once the target machine connects to the server and the payload is then executed. This module is versatile as it can target in various languages like Python, Powershell, and PHP applications.

To use this, type the following command:

Command: use exploit/multi/script/web_delivery

Also type “show options” command to view all required options.

Furthermore, you need to select the appropriate TARGET type which is PHP in our case as we’re targeting command injection in PHP based web application.

Here we selected Target value as 1 because of PHP payload and the payload in this case is “php/meterpreter/reverse_tcp“.

Metasploit has a PHP meterpreter payload. With this module, you can also create a PHP webshell that has meterpreter capabilities. You can then upload the shell to the target server using vulnerabilities such as command injection and file upload.

As soon as you execute run command, the server on our local machine starts and the last line is more important because this is only final payload or command which you need to execute on the target system as shown below:

So copy the last line and append it to the IP Address with && in command execution page under DVWA application.

If everything goes right, then you’ll successfully get the meterpreter reverse connection in your msfconsole window.

To view all meterpreter sessions, type “sessions -i” as shown below and we used the following command to interact with Session ID 1.

Command: sessions -i 1

If we had multiple hosts compromised, we could have multiple meterpreter sessions, interact with them, switch between them, or close them individually.

Now we will start the penetration testing procedure and perform the first step by starting to gather information about our victim machine. Type sysinfo to check the system information.

We can see the system information in the preceding screenshot, the computer name (Metasploitable) and the operating system (Linux) used by the victim.

Let’s try some more interesting activities in our Meterpreter session. Type “getuid” to check the system ID and the name of the victim machine.

After playing with the victim machine, now it is time for some serious stuff. We are going to access the victim’s command shell to control his/her system. For this, just type in shell and it will open a new command prompt for you.

Related Articles

SSL Kill is a forced man-in-the-middle transparent proxy that modifies HTTP requests and responses in order to avoid SSL and HSTS, to achieve that, it use a two-way ARP spoofing plus a forced DNS resolver that redirects all name server queries to the attacker IP Address. This tool is only for information security researchers and […]

There are plenty of ways to make your password secure, but most people just don’t bother. It is much easier to set a password that is easy to remember, but hackers rely on this to break into insecure sites. Try to at least make it hard to guess by making it eight characters or more, […]

Today, Wireless Network has become more and more present in open area or large companies and security enhancement is needed to control authentication and confidentiality. The 802.11 Working Group introduced the 802.11i amendment as the final stage of the Robust Security Network standard, superseded the old WEP technology. Today we’ll show you a detailed step by step […]

Disclaimer

Yeahhub.com does not represent or endorse the accuracy or reliability of any information’s, content or advertisements contained on, distributed through, or linked, downloaded or accessed from any of the services contained on this website, nor the quality of any products, information’s or any other material displayed,purchased, or obtained by you as a result of an advertisement or any other information’s or offer in or in connection with the services herein.